all publishers

mukul975

@mukul975 source repo

828 published skills · page 9 of 9

  1. ▌
    Exploiting Adcs With Certipy · mukul975 bundle
    Enumerate and exploit Active Directory Certificate Services ESC1 through ESC16 misconfigurations with Certipy, including SAN abuse, NTLM relay to web enrollment (ESC8), and golden certificate forgery.
    24.6k repo stars
  2. ▌
    Hunting Saas Sso Token Abuse · mukul975 bundle
    Detect SSO and OAuth token replay and SaaS lateral movement using identity telemetry from Microsoft Entra ID and Okta.
    24.6k repo stars
  3. ▌
    Implementing Cloud Waf Rules · mukul975 bundle
    Deploy and tune Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare to protect cloud-hosted applications against OWASP Top 10 attacks, including managed rule sets, custom rate limiting, bot management, and false positive reduction.
    24.6k repo stars
  4. ▌
    Securing AWS Iam Permissions · mukul975 bundle
    Hardens AWS IAM configurations to enforce least privilege access across cloud accounts, covering policy scoping, permission boundaries, Access Analyzer integration, and credential rotation.
    24.6k repo stars
  5. ▌
    Securing Kubernetes On Cloud · mukul975 bundle
    Hardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring.
    24.6k repo stars
  6. ▌
    Hunting For Webshell Activity · mukul975 bundle
    Hunt for web shell deployments on internet-facing servers by analyzing file creation in web directories, suspicious process spawning from web servers, and anomalous HTTP patterns.
    24.6k repo stars
  7. ▌
    Implementing AWS Security Hub · mukul975 bundle
    Deploy AWS Security Hub as a centralized cloud security posture management platform, aggregate findings from GuardDuty, Inspector, Macie, and third-party tools, enable security standards, configure automated remediation, and build compliance dashboards across multi-account AWS organizations.
    24.6k repo stars
  8. ▌
    Modeling Threats With Opencti · mukul975 bundle
    Model threat actors, intrusion sets, campaigns, and TTPs as a STIX 2.1 knowledge graph in OpenCTI using the pycti Python client, connectors, and import workers for structured cyber threat intelligence.
    24.6k repo stars
  9. ▌
    Moving Laterally With Netexec · mukul975 bundle
    Enumerate SMB, WinRM, LDAP, and MSSQL services, validate credentials, spray passwords, and execute commands on remote hosts using NetExec during authorized penetration tests.
    24.6k repo stars
  10. ▌
    Profiling Threat Actor Groups · mukul975 bundle
    Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources.
    24.6k repo stars
  11. ▌
    Securing Serverless Functions · mukul975 bundle
    Hardens serverless compute platforms (AWS Lambda, Azure Functions, Google Cloud Functions) by enforcing least privilege IAM roles, eliminating hardcoded secrets, scanning dependencies for vulnerabilities, validating input, securing function URLs, and enabling runtime monitoring.
    24.6k repo stars
  12. ▌
    Testing Cors Misconfiguration · mukul975 bundle
    Identify and exploit Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during authorized security assessments.
    24.6k repo stars
  13. ▌
    Building Soc Escalation Matrix · mukul975 bundle
    Build a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.
    24.6k repo stars
  14. ▌
    Defending Llms With Guardrails · mukul975 bundle
    Deploy Llama Guard, NeMo Guardrails, and LLM Guard as runtime input/output scanners to block jailbreaks, prompt injection, and toxic content in production LLM applications.
    24.6k repo stars
  15. ▌
    Detecting Dependency Confusion · mukul975 bundle
    Detect and prevent public-over-private name resolution in npm, PyPI, and Maven dependency manifests.
    24.6k repo stars
  16. ▌
    Detecting Shadow API Endpoints · mukul975 bundle
    Discover and inventory undocumented API endpoints by comparing live traffic against OpenAPI specs, scanning code repositories, and analyzing cloud configurations.
    24.6k repo stars
  17. ▌
    Generating And Analyzing Sboms · mukul975 bundle
    Generate CycloneDX and SPDX SBOMs from container images and filesystems, scan them for vulnerabilities with Grype, and sign attestations with Cosign for supply-chain trust.
    24.6k repo stars
  18. ▌
    Hunting For Ntlm Relay Attacks · mukul975 bundle
    Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying IP-to-hostname mismatches, Responder traffic signatures, SMB signing status, and suspicious authentication patterns across the domain.
    24.6k repo stars
  19. ▌
    Performing Ransomware Response · mukul975 bundle
    Executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening.
    24.6k repo stars
  20. ▌
    Performing Vlan Hopping Attack · mukul975 bundle
    Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.
    24.6k repo stars
  21. ▌
    Testing Websocket API Security · mukul975 bundle
    Tests WebSocket API implementations for security vulnerabilities including missing authentication, Cross-Site WebSocket Hijacking, injection attacks, and denial-of-service.
    24.6k repo stars
  22. ▌
    Analyzing Kubernetes Audit Logs · mukul975 bundle
    Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns.
    24.6k repo stars
  23. ▌
    Analyzing Linux Kernel Rootkits · mukul975 bundle
    Detect kernel-level rootkits in Linux memory dumps using Volatility3 plugins and live system scanners to identify hooked syscalls, hidden modules, and tampered structures.
    24.6k repo stars
  24. ▌
    Conducting API Security Testing · mukul975 bundle
    Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic using the OWASP API Security Top 10 framework.
    24.6k repo stars
  25. ▌
    Configuring Hsm For Key Storage · mukul975 bundle
    Configure Hardware Security Modules (HSMs) using the PKCS#11 standard interface for key generation, signing, encryption, and key management with both physical HSMs and SoftHSM2 for development.
    24.6k repo stars
  26. ▌
    Detecting Golden Ticket Forgery · mukul975 bundle
    Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades, abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM.
    24.6k repo stars
  27. ▌
    Operating Havoc C2 · mukul975 bundle
    Build and operate a Havoc C2 framework for authorized red-team engagements, including team server deployment, evasive Demon agent generation, and post-exploitation.
    24.6k repo stars
  28. ▌
    Operating Sliver C2 · mukul975 bundle
    Stand up a Sliver C2 server and listeners, generate cross-platform implants and beacons, and run post-exploitation, pivoting, and BOF/.NET tooling via the armory for adversary emulation.
    24.6k repo stars